Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.33% | — | OscommerceAI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is… | |
| Aplazada | Alta (7.5) | 0.41% | — | Multidots Product Attachment FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID. | |
| Aplazada | Alta (7.5) | 0.41% | — | AI Chatbot FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Aplazada | Media (5.3) | 0.40% | — | Woocommerce Paypal PaymentsAI | 1/8/2026 | 29/9/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This… | |
| Aplazada | Media (6.5) | 0.30% | — | Automattic Woocommerce PaymentsAI | 1/8/2026 | 26/8/2026 | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
| Aplazada | Media (5.3) | 0.30% | — | Direct Payments FOR WoocommerceAI | 1/8/2026 | 26/8/2026 | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,… | |
| Aplazada | Alta (8.8) | 0.81% | — | Subscriptions FOR WoocommerceAI | 1/8/2026 | 12/8/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only… | |
| Aplazada | Alta (8.1) | 0.39% | — | Product Feed Manager FOR WoocommerceAI | 31/7/2026 | 26/8/2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Aplazada | Media (6.1) | 0.18% | — | Ecommerce Fruits BazarAI | 30/7/2026 | 1/10/2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Ecommerce-project-with-php-and-mysqli-fruits-bazarAI | 30/7/2026 | 1/10/2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | |
| Aplazada | Alta (8.3) | 0.18% | — | Softtr Information Technology Trade LTD E-commerce PackAI | 30/7/2026 | 31/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49. | |
| Aplazada | Alta (8.2) | 0.44% | — | FTC Software IT Services FTC E-commerce Management PanelAI | 30/7/2026 | 30/7/2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| Aplazada | Alta (7.2) | 0.58% | — | Subscriptions FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible… | |
| Aplazada | Media (5.9) | 0.29% | — | Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily… | |
| Aplazada | Media (5.3) | 0.30% | — | Payu CommerceproAI | 29/7/2026 | 10/8/2026 | The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders. | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wpexperts Wholesale FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with… | |
| Aplazada | Media (4.4) | 0.52% | — | SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI | 28/7/2026 | 28/7/2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Media (6.5) | 0.37% | — | Yookassa Yukassa FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Stripe FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | |
| Aplazada | Crítica (9) | 0.67% | — | Facturone Para Woocommerce CON VerifactuAI | 27/7/2026 | 27/7/2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible… | |
| Aplazada | Alta (8.1) | 0.41% | 💥 PoC | Custom Fields Account Registration FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator… | |
| Aplazada | Media (6.5) | 0.79% | — | Themehigh Checkout Field Editor FOR WoocommerceAI | 25/7/2026 | 27/7/2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary… | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 24/7/2026 | 24/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… |